Skip to main content

CWE archive

CWE-78 CVEs

Programmatic archive

6,180 CVEs tagged with CWE-781,976 Critical, 3,126 High, 890 Medium, 188 Low, 0 Unrated.

CVE-2020-8797

Published Apr 23, 2020

Juplink RX4-1500 v1.0.3 allows remote attackers to gain root access to the Linux subsystem via an unsanitized exec call (aka Command Line Injection), if the undocumented telnetd s…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7350

Published Apr 22, 2020

Rapid7 Metasploit Framework versions before 5.0.85 suffers from an instance of CWE-78: OS Command Injection, wherein the libnotify plugin accepts untrusted user-supplied data via…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10511

Published Apr 15, 2020

HGiga C&Cmail CCMAILQ before olln-base-6.0-418.i386.rpm and CCMAILN before olln-base-5.0-418.i386.rpm contains insecure configurations. Attackers can exploit these flaws to access…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-9478

Published Apr 13, 2020

An issue was discovered in Rubrik 5.0.3-2296. An OS command injection vulnerability allows an authenticated attacker to remotely execute arbitrary code on Rubrik-managed systems.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6765

Published Apr 10, 2020

D-Link DSL-GS225 J1 AU_1.0.4 devices allow an admin to execute OS commands by placing shell metacharacters after a supported CLI command, as demonstrated by ping -c1 127.0.0.1; ca…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10603

Published Apr 9, 2020

WebAccess/NMS (versions prior to 3.0.2) does not properly sanitize user input and may allow an attacker to inject system commands remotely.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7615

Published Apr 7, 2020

fsa through 0.5.1 is vulnerable to Command Injection. The first argument of 'execGitCommand()', located within 'lib/rep.js#63' can be controlled by users without any sanitization…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7613

Published Apr 7, 2020

clamscan through 1.2.0 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the `_is_clamav_binary` function located within `Index.js`. It sh…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 4,826-4,850 of 6,180 CVEsPage 194 of 248